search

Segregation of Duties in Payroll: Preventing Internal Fraud

7/18/2026

Segregation of duties is the single most effective control in payroll, and the reason is structural rather than theoretical: nearly every internal payroll fraud requires one person to control both a change and a payment. Separate those two capabilities and the scheme requires collusion, which is substantially rarer and substantially riskier for everyone involved.

That makes this control unusual. Most controls reduce the probability of a loss. This one removes the mechanism.

The Four Functions to Separate

  1. Authorization. Approving the hire, the termination, the rate change, the bonus. Belongs outside payroll entirely — with the hiring manager, HR, or an executive depending on the change.
  2. Recording. Entering the employee record, the rate, the deduction, the bank details into the payroll system.
  3. Custody. Releasing the payroll, transmitting the ACH file, signing checks, initiating the tax deposit.
  4. Reconciliation. Reconciling the payroll bank account and the payroll register to the general ledger.

The critical separations, in order of importance:

  • Recording must be separate from custody. This is the one that prevents fraud. A person who can both create a payment and release it has everything required.
  • Authorization must be separate from recording. Otherwise someone can invent the change they then enter.
  • Reconciliation must be separate from both recording and custody. Otherwise the person who created a discrepancy is the person who reports whether one exists.

What Each Combination Enables

Making the risk concrete clarifies why the separations matter.

Recording + custody enables ghost employees, unauthorized rate changes, and pay diversion. The perpetrator creates or alters a record and then causes payment. This is the combination present in most internal payroll fraud cases. See our ghost employee guide.

Authorization + recording enables fabricated approvals — a rate change with a self-generated authorization, or a bonus nobody outside the process approved.

Recording + reconciliation enables concealment. An error or diversion can be hidden in a reconciliation the perpetrator prepares.

Custody + reconciliation enables misappropriation of the bank balance itself, concealed in the reconciliation.

Time approval + time recording enables inflated hours. Where a supervisor both records and approves their subordinates' time — or approves without reviewing — the control does not exist regardless of what payroll does downstream. See our timecard fraud guide.

Note that the last combination sits outside the payroll department entirely, which is why segregation of duties must be assessed across the whole process rather than within payroll's own walls.

The Small Department Problem

Most payroll departments have one to three people, and full four-way segregation is not achievable. The answer is not to abandon the control; it is to place the separations where they matter most and compensate elsewhere.

The one separation to achieve regardless of size: recording from custody.

Practical approaches:

The release approval sits outside payroll. A controller, CFO, office manager, or owner reviews the pre-release variance report and authorizes the release. This is the highest-value separation and it does not require payroll expertise — the reviewer is confirming that changes are explained, not recalculating withholding.

The bank reconciliation sits outside payroll. Accounting reconciles the payroll account. This is usually easy to arrange and is a genuine detective control.

Authorization sits with the hiring manager or HR, evidenced by a document.

Bank detail changes require a second person's verification, through a channel other than the one the request arrived on.

Positive pay or dual bank authorization for the payroll account, so a single person cannot originate a transfer.

In a one-person department, the separation must come from outside — an owner, an executive, or an external accountant reviewing the register and authorizing release. A one-person payroll function with no external review has no meaningful fraud control, and this should be stated plainly to whoever accepts that risk.

Compensating Controls

Where a separation genuinely cannot be achieved, compensating controls reduce but do not eliminate the exposure. They must be documented as compensating rather than presented as equivalent.

Mandatory vacation for payroll staff, with the cycle run by someone else. One of the few controls that surfaces a scheme without anyone looking for one, and among the cheapest available.

Periodic job rotation where more than one person can process.

Independent headcount confirmation — department managers verifying the employees charged to their teams. This detects a fabricated employee that payroll-to-HR reconciliation cannot, since a person invented in both systems reconciles perfectly.

Duplicate bank account and address testing, quarterly.

Rate change reconciliation against approved HR records, every cycle.

Terminated employee payment check against HR's separation list, every cycle.

Access logging with independent review, particularly access to records the person has no business reason to view.

Surprise reviews by management or internal audit.

An anonymous reporting channel. A meaningful share of frauds are discovered through a tip rather than a control.

External review — an annual review by an accountant or consultant, which also produces the documentation that supports a reasonable-care position.

See our fraud detection guide and How to Prevent Payroll Fraud.

System Access Design

Segregation of duties fails in practice through access rather than through org charts. An organization can have a clean separation on paper and grant one person the system rights to do everything.

Points to verify:

Role-based access mapped to the separation. The person recording changes should not have release rights, and this should be enforced by the system rather than by policy.

Administrator rights are the common gap. A payroll administrator with full system rights can typically do everything regardless of the intended design. Restrict administrative access, log its use, and have that log reviewed by someone else.

Emergency and break-glass access should exist, be logged, and be reviewed after every use.

Access removed on departure and role change, promptly. An active account for a departed administrator is a serious failure and a routine audit finding.

Periodic access review comparing granted rights against current roles. Rights accumulate as people change jobs, and nobody removes the old ones.

Provider portal access counts. Where a payroll provider processes the payroll, whoever can approve in the provider's portal holds custody regardless of your internal system design.

Documenting It

For SOX purposes and for penalty abatement purposes alike, the control must produce evidence that it operated.

A documented matrix of the four functions against the people who perform them, reviewed at least annually and whenever staffing changes.

Evidence per cycle — the release approval signed and dated, the variance report initialed, the reconciliation completed and reviewed. A control that operated without leaving a mark is untestable, and untestable is treated as absent.

Documented compensating controls where a separation is not achievable, with the rationale stated.

Consistency. A control performed in two of four quarters is a deficiency regardless of how well it is designed.

See our SOX compliance guide and Best Practices For Payroll Policies And Procedures.

The Conversation to Have

Segregation of duties is frequently resisted for a specific and understandable reason: it implies distrust of a long-tenured, reliable, indispensable employee. That framing is worth addressing directly, because it is the reason the control is so often absent.

Two points that resolve it:

The control protects the employee. A payroll professional who is the only person with access to everything is the only suspect when a discrepancy appears. Separation means an error is investigated rather than attributed.

It is a structural requirement, not a judgment. Every organization implements it regardless of who holds the role, for the same reason two signatures are required on large checks — not because the signatories are suspected, but because the control cannot depend on assessing individuals.

The profile in most payroll fraud cases is a long-tenured, trusted, indispensable employee. That is not a coincidence and it is not a reason to distrust anyone in particular. It is the reason the control must be structural.

Assessing Your Current State

A structured self-assessment takes an hour and produces a clear answer. Work through it honestly rather than aspirationally — the value is entirely in accuracy.

List every person who touches payroll, including outside the department: HR staff, department managers who approve time, finance staff, executives with system access, and any external provider personnel.

For each person, record what they can actually do, verified in the system rather than assumed from their role:

  • Add or reactivate an employee record
  • Change a pay rate
  • Change bank details
  • Enter or edit time
  • Approve time
  • Release the payroll or approve it in a provider portal
  • Initiate a bank transfer or tax deposit
  • Reconcile the payroll bank account
  • Reconcile the register to the general ledger
  • Administer the system, including granting others' access

Then look for the fatal combinations: anyone who can both alter a record and cause payment; anyone who can both approve and record time; anyone who can both cause payment and reconcile the account; and anyone whose administrative rights let them do all of it regardless of the intended design.

Include the provider portal. Whoever can approve in a provider's portal holds custody, whatever your internal system shows.

Include emergency and delegated access — the rights someone holds while covering for an absence, which frequently remain after the absence ends.

Where a fatal combination exists and cannot be eliminated, write down which compensating controls address it and who performs them. Where none exists, that is the finding, and it should be reported to whoever accepts the risk rather than absorbed silently by the payroll department.

Frequently Asked Questions

What is segregation of duties in payroll?

Separating four functions so no single person controls a transaction end to end: authorization of changes, recording them in the system, custody of the payment release, and reconciliation. The critical separation is recording from custody — a person who can both create or alter a record and cause payment has everything required for nearly every internal payroll fraud.

Why is segregation of duties the most important payroll control?

Because it removes the mechanism rather than reducing the probability. Nearly every internal payroll fraud requires one person to control both a change and a payment, so separating those capabilities means the scheme requires collusion — substantially rarer and riskier for all participants. Most other controls detect fraud after it has occurred; this one prevents the combination that enables it.

How can a small payroll department achieve segregation of duties?

Achieve the recording-from-custody separation regardless of size, and place the release approval outside payroll — a controller, office manager, or owner reviewing the pre-release variance report and authorizing release. That reviewer needs no payroll expertise, since they are confirming changes are explained rather than recalculating withholding. Also move the bank reconciliation to accounting, and require a second person to verify bank detail changes.

What if segregation of duties is impossible?

Use documented compensating controls, labelled as compensating rather than presented as equivalent: mandatory vacation with the cycle run by someone else, independent headcount confirmation by department managers, quarterly duplicate bank account and address testing, per-cycle rate change and terminated-employee reconciliation, access logging with independent review, an anonymous reporting channel, and an annual external review. A one-person function with no external review has no meaningful fraud control, and that should be stated plainly.

Does system access affect segregation of duties?

Decisively — this is where the control usually fails in practice. An organization can have a clean separation on paper while granting one person the system rights to do everything. Administrator rights are the common gap, since a payroll administrator with full rights can typically bypass the intended design. Restrict administrative access, log its use, have the log reviewed by someone else, and include provider portal access in the assessment.

How do you address resistance to segregation of duties?

Directly, since the resistance usually reflects a concern that the control implies distrust of a valued employee. Two points resolve it: the control protects the employee, because someone who is the only person with full access is the only suspect when a discrepancy appears; and it is structural rather than a judgment, implemented regardless of who holds the role for the same reason two signatures are required on large checks.

Going Deeper

Assess segregation across the whole process rather than within payroll alone, verify it in system access rather than only on the org chart, and ensure each separation leaves durable evidence that it operated.

PayrollTrainingCenter.com
mailing address
9715 Rod Road Suite A Alpharetta, GA 30022
phone1-770-410-1219 emailsupport@PayrollTrainingCenter.com
Trusted Provider Of
Stay Up To Date
Need Training Or Resources In Other Areas? Try Our Other Training Center Sites:
HR Accounting Banking Mortgage Insurance Financial Services For TPAs Safety
Training By Delivery Format & Subjects Covered:
Special Promotions Online Training Resource Materials SeminarsWebinars All Payroll Subjects
Facebook Copyright PayrollTrainingCenter.com 2026